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UNITED STATES DISTRICT COURT 
NORTHERN DISTRICT OF CALIFORNIA 
OAKLAND DIVISION 



INTERTRUST TECHNOLOGIES 
CORPORATION, a Delaware corporation, 

Plaintiff, 



MICROSOFT CORPORATION, a 
Washington Corporation, 

Defendant 



CASE NO: C 01-1640 SBA 

MICROSOFT CORPORATION'S 
FIRST AMENDED ANSWER AND 
COUNTERCLAIMS TO THE SECOND 
AMENDED COMPLAINT 



Defendant Microsoft Corporation ("Microsoft") answers the Second Amended 
Complaint of InterTrust Technologies Corporation ("InterTrust") as follows: 

1 . Microsoft admits that the Second Amended Complaint purports to state a 
cause of action under the patent laws of the United States, 35 United States Code, §§ 271 and 



n 1 281. Microsoft denies that it has infringed or now infringes the patents asserted against Microsoft 

ORRICK ~ 1 DOCSSV1:1600»6.1 (vllCKOSOFT CORPORATION'S FlftST AMENDED ANSWER 

HERR.NGTON | AND COtT^ R CUMMS.CA S ENo.C0l-l640SBA 

Si Si TCLiFrc LLr n 



1 

2 
3 
4 
5 
6 
7 
8 
9 
10 
11 
12 
13 
14 
15 
16 
17 
18 
19 
20 
21 
22 
23 
24 
25 



0 FAX 415 394 0134 KEKER & VAN NEST LLP @003 



i the Second Amended Complaint. Microsoft denies any and all remaining allegations of 
aragraph 1 of the Second Amended Complaint. 

2. Microsoft admits that the Second Amended Complaint purports to state a 
ause of action over which this Court has subject matter jurisdiction under 28 U.S.C. §§ 1331 and 
338(a). 

3 . Microsoft admits, for purposes of this action only, that venue is proper in 
his judicial district Microsoft denies any and all remaining allegations of paragraph 3 of the 
Second Amended Complaint. 

4. Upon information and belief, Microsoft admits the allegations of paragraph 

( of the Second Amended Complaint. 

5. Microsoft admits the allegations of paragraph 5 of the Second Amended 

Complaint. 

6. Microsoft admits, for purposes of this action only, that it transacts business 
n this judicial district. Microsoft denies any and all remaining allegations of paragraph 6 of the 
Second Amended Complaint. 

7. Microsoft admits that on its face the title page of U.S. Patent No. 6,1 85,683 
31 ("the '683 Patent") states that it was issued February 6, 2001, is entitled "Trusted and secure 
echniques, systems and methods for item delivery and execution," and lists "InterTrust 
rechnologies Corp." as the assignee.. Microsoft admits that a copy of the *683 Patent was 
ittached to the copy of the Second Amended Complaint delivered to counsel for Microsoft, but 
lenies that such copy was full and complete insofar as it did not include any material purportedly 
ncorporated by reference therein. Microsoft denies that the '683 Patent was duly and lawfully 
ssued. Microsoft further denies any and all remaining allegations of paragraph 7 of the Second 
Amended Complaint. 

8. Microsoft admits that on its face the title page of U.S. Patent No. 6.253,193 
Bl ("the ' 1 93 Patent") states that it was issued June 26, 2001 , is entitled "Systems and methods 
for the secure transaction management and electronic rights protection," and lists "InterTrust 
Technologies Corporation" as the assignee. Microsoft admits that a copy of text associated with 
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the '193 Patent was attached to the copy of the Second Amended Complaint delivered to counsel 
for Microsoft, but denies that such copy was full and complete as it did not include, among other 
things, any of the drawings or figures. Microsoft further denies such copy was full and complete 
insofar as it did not include any material purportedly incorporated by reference therein. Microsoft 
denies that the ' 193 Patent was duly and lawfully issued. Microsoft further denies any and all 
remaining allegations of paragraph 8 of the Second Amended Complaint. 

9. Microsoft admits that on its face the title page of U.S. Patent No. 5,940,504 
("the '504 Patent") states that it was issued August 17, 1999 and is entitled 'licensing 
management system and method in which datagrams including an addressee of a licensee and 
indicative of use of a licensed product are sent from the licensee's site." Microsoft admits that a 
copy of the '504 Patent was attached to the copy of the Second Amended Complaint delivered to 

12 | counsel for Microsoft. Microsoft denies that the '504 Patent was duly and lawfully issued. 

1 3 J Microsoft further denies any and all remaining allegations of paragraph 9 of the Second Amended 

14 | Complaint. 

10. Microsoft admits that on its face the title page of U.S. Patent No. 5,920,861 
("the '861 Patent") states that it was issued July 6, 1999, is entitled "Techniques for defining, 
using and manipulating rights management data structures," and lists "InterTrust Technologies 

1 8 Corp." as the assignee. Microsoft admits that a copy of the *86 1 Patent was attached to the copy 
of the Second Amended Complaint delivered to counsel for Microsoft, but denies that such copy 
was full and complete insofar as it did not include any material purportedly incorporated by 
reference therein. Microsoft denies that the *861 Patent was duly and lawfully issued. Microsoft 

22 | further denies any and all remaining allegations of paragraph 1 0 of the Second Amended 

23 Complaint. 

1 1 . Microsoft repeats and reasserts its responses to paragraphs 1 -7 of the 
Second Amended Complaint, as if fully restated herein. 

12. Microsoft admits that the Second Amended Complaint purports to state a 
cause of action under 35 U.S.C. §§ 271 and 281. Microsoft denies that it has infringed or now 
infringes the patents asserted against Microsoft in the Second Amended Complaint. Microsoft 
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I denies any and all remaining allegations of paragraph 12 of the Second Amended Complaint 
13. Microsoft denies any and all allegations of paragraph 13 of the Second 



3 j Amended Complaint. 
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1 4. Microsoft denies any and all allegations of paragraph 14 of the Second 

Amended Complaint. 

15. Microsoft denies any and all allegations of paragraph 15 of the Second 

Amended Complaint. 

16. Microsoft denies any and all allegations of paragraph 16 of the Second 

Amended Complaint. 

17. Microsoft denies any and all allegations of paragraph 17 of the Second 

11 | Amended Complaint. 

12 I 18. Microsoft repeats and reasserts its responses to paragraphs 1*6 and 8 of the 

1 3 Second Amended Complaint, as if fully restated herein. 

j 4 19, Microsoft admits that the Second Amended Complaint purports to state a 

cause of action under 35 U.S.C. §§ 271 and 281. Microsoft denies that it has infringed or now 
infringes the patents asserted against Microsoft in the Second Amended Complaint Microsoft 
denies any and all remaining allegations of paragraph 19 of the Second Amended Complaint 

20. Microsoft denies any and all allegations of paragraph 20 of the Second 
19 Amended Complaint. 

2 1 . Microsoft denies any and all allegations of paragraph 21 of the Second 

Amended Complaint. 

22. Microsoft denies any and all allegations of paragraph 22 of the Second 

Amended Complaint. 

23 . Microsoft denies any and all allegations of paragraph 23 of the Second 

Amended Complaint. 

24. Microsoft denies any and all allegations of paragraph 24 of the Second 

Amended Complaint 
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25 . Microsoft repeats and reasserts its responses to paragraphs 1 -6 and 9 of the 
Second Amended Complaint, as if fully restated herein. 

26. Microsoft admits trial the Second Amended Complaint purports to state a 
cause of action under 35 U.S.C. §§271 ajid 281. Microsoft denies that it has infringed or now 
infringes the patents asserted against Microsoft in the Second Amended Complaint. Microsoft 
denies any and all remaining allegations j>f paragraph 26 of the Second Amended Complaint. 

27. Microsoft denies any and all allegations of paragraph 27 of the Second 
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Amended Complaint. 

28. Microsoft denies any and all allegations of paragraph 28 of the Second 

i 

i 

Amended Complaint j 

29. Microsoft denies isxy and all allegations of paragraph 29 of the Second 

Amended Complaint 

30. Microsoft denies any and all allegations of paragraph 30 of the Second 

i 

Amended Complaint. 

3 1 . Microsoft denies any and all allegations of paragraph 3 1 of the Second 

Amended Complaint. 

32. Microsoft repeatsjand reasserts its responses to paragraphs 1-6 and 10 of 
the Second Amended Complaint, as if fiilly restated herein. 

33 . Microsoft admits that the Second Amended Complaint purports to state a 
of action under 35 U.S.C. §§ 271 ind 281. Microsoft denies that it has infringed or now 

infringes the patents asserted against Microsoft in the Second Amended Complaint. Microsoft 
denies any and all remaining allegations! of paragraph 33 of the Second Amended Complaint. 

34. Microsoft denies 'any and all allegations of paragraph 34 of the Second 

Amended Complaint. j 

35. Microsoft denies 'any and all allegations of paragraph 35 of the Second 

Amended Complaint. 

36. Microsoft denies any and all allegations of paragraph 36 of the Second 
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37. Microsoft denies any and all allegations of paragraph 37 of the Second 

Amended Complaint. 

38. Microsoft denies any and all allegations of paragraph 38 of the Second 

Amended Complaint. 

AFFIRMATIVE AND OTHER DEFENSES 
Further answering the Second Amended Complaint, Microsoft asserts the 
following defenses. Microsoft reserves the right to amend its answer with additional defenses as 
further information is obtained. 

First Defense: Noninfringement of the Asserted Patents 

1 . Microsoft has not infringed, contributed to the infringement of, or induced 
the infringement of US. Patent No. 6,185,683 Bl ('the '683 Patent"), US. Patent No. 6,253,193 
Bl ('the 8 193 Patenf), US. Patent No. 5,940,504 ("the '504 Patent") or US. Patent No. 
5,920,861 ("the '861 Patent"), and is not liable for infringement thereof 

2. Any and all Microsoft products or actions that are accused of infringement 

15 1 have substantial uses that do not infringe and therefore cannot induce or contribute to the 

16 I infringement of the '683 Patent, the 4 193 Patent, the '504 Patent or the '861 Patent. 
j7 [ Second Defense; Invalidity of the Asserted Patents 
18 ll 3. On information and belief, the '683 Patent, the '193 Patent, the '504 Patent 

.19 I and the 4 861 Patent are invalid for failing to comply with the provisions of the Patent Laws, Title 
35 US.C, including without limitation one or more of 35 US.C §§ 102, 103 and 112. 

Third Defense: Unavailability of Relief 

4. On information and belief, Plaintiff has failed to plead and meet the 
requirements of 35 US.C. § 271(b) and is not entitled to any alleged damages prior to providing 
any actual notice to Microsoft of the *683 Patent the 4 193 Patent, the 4 504 Patent or the '861 
Patent. 

Fourth Defense: Unavailability of Relief 

5. On information and belief, Plaintiff has failed to plead and meet the 
78 J requirements of 35 US.C. § 284 for enhanced damages and is not entitled to any damages pnor <o 
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■oviding any actual notice to Microsoft of the *683 Palent, the '193 Patent, the <504 Patent, 
id/or the '861 Patent, and any alleged infringement thereof. 

Fifth Defease! Unavailability of Relief 
6 . On information and belief, Plaintiff has felled to plead and meet the 
iquirements of 35 U.S.C § 287, and has btherwise failed to show that it is entitled to any 
amages. 

Sixth Defense: Prosecution Histo ry Estoppel 

7. Plaintiffs alleged causes of action for patent infringement are haired under 

ic doctrine of prosecution history estoppel, and Plaintiff is estopped from claiming that the '683 

atent, the '193 Patent, the '504 Patent, and/or the '861 Patent covers or includes any accused 

/ficrosoft product or method. 

Seventh Defense: Dedication to the Public 

8. Plaintiff has dedicated to the public all methods, apparatus, and products 
isclosed in the '683 Patent, the '193 Patent, the '504 Patent, anoVor the '861 Patent, but not 
iterally claimed therein, and is estopped from claiming infringement by any such public domain 
nethods, apparatus, and products. 

Eighth Defense: Use/Manufacture Bv/For United States Government 

9. To the extent that any accused product has been used or manufactured by 
>r for the United States, Plaintiffs claims and demands for relief are barred by 28 U,S.C § 1498. 

Ninth Defense: License 

1 0. To the extent that any of Plaintiff s allegations of infringement are 

i 

remised on the alleged use, sale, or offer for sale of products that were manufactured by or for a 
icensee of InterTnxst and/or provided by or to Microsoft to or by a licensee of InterTrust, such 
illegations are barred pursuant to license. 

Tenth Defense: Acquiescence 

1 1 . Plaintiff has acquiesced in at least those acts of Microsoft that are alleged 
Lo infringe the '861 Patent, the '683 Patent, and the 4 193 Patent. 
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Eleventh Defense: Laches 



12. 

doctrine of laches. 



Plaintiff's claims foj- relief are barred, in whole or in part, by the equitable 



I 



1 
2 
3 

. Twelfth- Defense: Inequitable Conduct 

5 .J i2. The '861 Patent claims are unenforceable due to inequitable conduct, 

6 including those acts and failures to act setforth in Microsoft's Counterclaim for Declaratory 
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Judgment of Unenforceability of the '861 Patent, set forth below. 

• COUNTERCLAIMS 

COUNT I - DECLARATORY 
JUDGMENT OF NONINFRINGEMENT 

1 . This action arises under the patent laws of the United States, Title 35 



U.S.C. §§ 1, et seq. This Court has subject matter jurisdiction over this counterclaim under 28 
U.S.C. §§ 1338, 2201, and 2202. . 

2. Microsoft Corporation ("Microsoft") is a Washington corporation with its 

principal place of business in Redmond, Washington. 

j 

3. Upon information jand belief; Plaintiff /Counterclaim Defendant InterTrust 
Technologies Corporation ("InterTrust ,T ) is a Delaware corporation with its principal place of 

18 | business in Santa Clara, California. 

4. InterTrust purports to be the owner of U.S. Patent Nos. 6,185,683 Bl ("the 
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25 1 of the '683 Patent, the • 193 Patent,' the '504 Patent, or the «861 Patent, and Microsoft is not liable 

26 I for infringement thereof. 

27 (/// 
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'683 Patent"), 6,253.193 Bl ("the '193 Patent"), 5,940,504 ("the *504 Patent"), and 5,920,861 

i i 

("the '861 Patent"). ! 

5. InterTrust alleges that Microsoft has infringed the '683 Patent, the '193 

Patent, the '504 Patent, and the '86jl Patent. 

6. No Microsoft prot met has infringed, either directly or indirectly, any claim 
L 
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! ■ . 7. An actual controversy, within the meaning of28U.S.C.§§ 2201 and 2202, 

2 exists between Microsoft, on the one hand, and InterTrust, on the other hand, with respect to the 

3 infringement or nonmfringement of the '683 Patent, the '193 Patent, the '504 Patent, and/or the 
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•861 Patent. 



COUNT II - DECLARATORY 
JUDGMENT OF INVALIDITY OF THE '683 PATENT 



8. Microsoft repeats and realleges paragraphs 1-5 of its Counterclaims, as if 

fully restated herein. 

9. The '683 Patent, and each claim thereof, is invalid for failing to comply 
with the provisions of the Patent Laws, including one or more of 35 U.S.C §§ 102, 103 and 1 12. 

10. An actual controversy, within the meaning of 28 U.S.C. §§ 2201 and 2202, 
exists between Microsoft, on the one handj and InterTrust, on the other hand, with respect to 
whether the claims of the '683 Patent are Valid or invalid. 

COUNT HI - DECLARATORY 
JUDGMENT OF INVALIDITY OF THE '193 PATENT 

1 1 . Microsoft repeats and realleges paragraphs 1 -5 of its Counterclaims as if 

fully restated herein. 

12. The ' 1 93 Patent, and each claim thereof, is invalid for failing to comply 
with the provisions of the Patent Laws, including one or more of 35 U.S.C. §§ 102, 103 and 1 12. 

13. An actual controversy, within the meaning of 28 U.S.C. §§ 2201 and 2202, 
exists between Microsoft, on the;one hand, and InterTrust, on the other hand, with respect to 
whether the claims of the '193 Patent are valid or invalid. 

. COUNT IV - DECLARATORY 
JUDGMENT OF INVALIDITY OF THE '504 PATENT 

14. Microsoftre'peats and realleges paragraphs 1 -5 of its Counterclaims as if 

fully restated herein. 

15. - The '504 Patent, and each claim thereof, is invalid for failing to comply 
With the provisions of the Patent Laws, including one or more of 35 U.S.C. §§ 102, 103 and U2. 
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16. An actual controversy, within the meaning of 28 U.S.C §§ 2201 and 2202,. 



cists between Microsoft, on the one hand ; 



and InterTrust, on the other hand, with respect to 



hether the claims of the '504 Patent are valid or invalid. 

COUNT W - DECLARATORY 
JUDGMENT OF 1NVAL1DTTY OF THE '861 PATENT 



ill 



17. Microsoft repeats rfcjd reaUeges paragraphs 1-5 of its Counterclaims as if 

illy restated herein. ^ 

18: The '861 Patent, ajpji each claim thereof, is invalid for failing to comply 
nth the provisions of the Patent Laws, iripluding one or more of 35 U.S.C. §§ 102, 103 and 112. 

19. An actual controversy, within the meaning of 28 U-S.C. §§ 2201 and 2202, 



xists between Microsoft, on the one hand 



and InterTrust, on the other hand, with respect to 



whether the claims of the '861 Patent areyalid or invalid. 

COUNT VI - DECLARATORY JUDGMENT 
OF UNENFORCEABILITY OF THE '861 PATENT 

20. Microsoft repeats knd realleges paragraphs 1-5 of its Counterclaims, as if 

ully restated herein. ! . j 

' ! I't 

21. Claims 1-129 of tfaS '861 Patent application (SN 08/805,804), and claims 

: i-li 

i-101 of the *861 Patent, were ndt.and are! not entitled to benefit of any application filing date 
mor to February 25, 1 997, under 35 U.sip. § 120 or otherwise, 

22. Exhibit A'hereto is a reprint of an article entitled "Digibox: A Self- 
protecting Container for Infonnatipn Co fnmerce/* The article shown in Exhibit A (hereafter, 
the Sibert article") was published m Juty 1995 in the Proceedings of the First USENK 
Workshop on Electronic Commerce. ! 

23 On information and belief, the content of pages 2-1 4 of Exhibit A was 

; !■ I- 

presented at a public conference in the United States in July 1995. 

24. Exhibit B hereto is- a copy of a page from an International Application 
published under the Patent Cooperation Treaty (PCT). bearing International Publication Number 
WO 96/27155. 

DOCS$vi:t6009Ci Microsoft Coloration's First amended answer 
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25. ' On information andibelief, International AppUcation WO 96/27155 has, at 
all times since its filing date, been oWned 4pd controlled by InterTnist or its predecessors in 

! i 

interest. i; ; < 

26. International kpplidation WO 96/27155 (hereafter '.the WO 96/27155 

! : 

(PCT) publication") was published on September 6, 1996. 

27. United States' PateJt No. 5,910,987 ('the '987 Patent") issued on June 8. 
7 1 1999, from a continuation of an app|licaticn filed on February 13, 1995. 

28. The Sibert article is prior art to claims 1-129 of the '861 Patent application 
(SN 08/805,804), and claims MOljbf the '861 Patent, under 35 U.S. C §§ 102(b), 103.. 

29. The WO 96/2715s!(PCT) publication is prior ait to claims 1-129 of the 
'861 Patent application (SN 08/805j,804)jand claims 1-101 of the '861 Patent, under 35 U.S.C §§ 

102(a), 103. |; ] : 

30. The '987 Patent is jpnor ail to claims 29-129 of the '861 Patent application 
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(SN 08/805,804), and claims l-lOljof thei'861 Patent, under 35 U.S.C. §§ 102(e), 103. 

If |; 
3 1 . The Sibert article *jas material to the patentability of claim 1 of the '861 
I i : 
Patent application (SN 08/805,804). j ; 
32. The Sibert article was material to the patentability of claims 2-129 of the 
'861 Patent application (SN 08/805,804)1 ] 
33. The WO 96/27155;(PCT) publication was material to the patentability of 
claim 1 of the '861 Patent application (Sljl 08/805,804). 
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34 The WO 96)27 1 55; (PCT) publication was material to the patentability of 

li 

claims 2-129 of the '861 Patent application (SN 08/805,804). 

|; 

35. The '987 Patent was material to the patentability of claims 29-129 of the 

"; i :" 

'861 Patent application (SN 08/805,804)} 

•i i : 

36. One or more of the '861 Patent applicants knew, while the '861 Patent 
application (SN 08/805,804) was pending, of the July 1995 publication of the Sibert article. 

37. On information and belief, one or more of the ' 861 Patent applicants knew, 
while the '861 Patent application (SN 08/805,804) was pending, of the September 1996 
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ublication of the WO 96/2715 5 (PCT) publication. 



38. One or more of the 
pplication (SN 08/805,804) was pending; 

39. On information anc 



861 Patent applicants knew, while the '861 Patent 
of the June 8, 1999 issuance of the 4 987 patent 
belief; one or more of the attorneys who prosecuted or 
ssisted in prosecuting the '861 Patent application (SN 08/805,804) knew, while that application 
vas pending, of the July 1995 publication of the Sibert article. 

40. One or more of the attorneys who prosecuted or assisted in prosecuting the 
861 Patent application (SN 08/805,804) bew, while that application was pending, of the 
September 1996 publication of the WO 96/27155 (PCT) publication. 

41 . One or more of the attorneys who prosecuted or assisted in prosecuting the 
861 Patent application (SN 08/805,804) knew, while that application was pending, of the June 8, 
L999 issuance of the '987 patent, j 

42. The applicants for the '861 Patent did not cite the Sibert article, the WO 
)6/21 155 (PCT) publication, or the '987 Patent to the Patent Office as prior art to any of claims 1- 
L29 of the *861 Patent application (SN 08/805,804). 

43. The applicants for the '861 Patent did not cite to the Patent Office as prior 
irt to any of claims 1-129 of the *86l Parent application (SN 08/805,804) any reference having 
the same or substantially the same disclosure as the Sibert article, the WO 96/27155 (PCT) 
publication, or the '987 Patent. 

44. None of the Sibert article, the WO 96/27155 (PCT) publication, or the *987 
Patent is merely cumulative over any reference cited as prior art during the prosecution of the 
l 86l Patent application (SN 08/805,804). 

45. On information and belief, one or more of the '86 1 Patent applicants 
believed, during pendency of claim : l of the *861 Patent application (SN 08/805,804), that the 
Sibert article disclosed an embodiment of claim 1 of the '861 Patent application (SN 08/805,804). 

46. On information and belief, one or niore of the 4 861 Patent applicants 
believed, during pendency of claim 1 of the '861 Patent application (SN 08/805,804), that the 
WO 96/27155 (PCT) publication disclosed an embodiment of claim 1 of the '861 Patent 
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47. On information and 
believed, while the '861 Patent application 



48. 

believed, while the '861 Patent application 
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belief, one or more of the '861 Patent applicants 
(SN 08/805,804) was pending, that the Sibert article 
was material to the patentability of claims 1-129 of the '861 Patent application (SN 08/805,804), 
but, with deceptive intent, failed to disclose that reference as prior art to the Patent Office. 

On information and belief, one or more of the '861 Patent applicants 

(SN 08/805,804) was pending, that the WO 96/27155 
(PCT) publication was material to the patintabiUty of claims 1-129 of the '861 Patent application 
(SN 08/805,804), but, with deceptive intent, failed to disclose that reference as prior art to the 
Patent Office. 

49. On information and belief, one or more of the '861 Patent applicants 
believed, while the '861 Patent applicatio: i (SN 08/805,804) was pending, that the '987 Patent 

29-129 of the «861 Patent application (SN 08/805,804), 
14 but, with deceptive intent, failed to disclose that reference as prior art to the Patent Office. 

50. The '861 Patent is ^enforceable due to the inequitable conduct of the ' 8 6 1 
Patent applicants before the Patent and Trademark Office in connection with the '861 Patent 
application (SN 08/805,804). 

51. An actual controversy, within the meaning of 28 U.S.C. § § 2201 and 2202, 
exists between Microsoft, on the one hank and InterTrust, on the other hand, with respect to 
whether the claims of the '861 Patent are[enforceable. 
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COUNT jvil - INFRINGEMENT 
OF U.S. PATENT NO. 6.049,671 

52. Microsoft repeats Ld realleges paragraphs 2-3 of its Counterclaims, as if 
fully restated herein. 

53 . This Court has exclusive subject matter jurisdiction over Microsoft's cause 
of action for patent infringement under ijitle 28. United States Code, Sections 1331 and 1338, and 
under the patent laws of the United States, Title 35 of the United States Code. 
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54. U.S. Patent No. 6,049,671 ("the '671 Patent") issued to Microsoft 
Corporation as the assignee of Benjamin >f Slivka and Jeffrey S. Webber on April 1 1, 2000. 

55. a true copy of foe '671 Patent is attached as Exhibit C hereto, and is 

incorporated herein by reference. ; 

56. Microsoft owns all right, title and interest in the *671 Patent 

57. InterTrust has had actual notice of the 4 671 Patent 

58. InterTrust has infringed one or more claims of the '671 Patent, in violation 

of at least 35 U-S.C. § 271(a, b, c). 

59. InterTrust's infringement of the *671 Patent has caused and will continue to 
cause Microsoft damage, including irrepalable harm for which it has no adequate remedy at law. 



"I 
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COUNT ym - INFRINGEMENT 
OF tj.S. PATF.NT NO. 6JS6.668 



60. Microsoft repeals and realleges paragraphs 2-3 and 51 of its Counterclaims, 

as if fully restated herein. 

61. U.S. Patent No. 6,256,668 Bl ("the *668 Patent") issued to Microsoft 

Corporation as the assignee of Benjamin W. Slivka and Jeffrey S. Webber on July 3, 2001. 

62. A true copy of the 1*668 Patent is attached as Exhibit D hereto, and is 
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63 . Microsoft owns all right, title and interest in the '668 Patent. 

64. InterTrust has had[actual notice of the 4 668 Patent. 

65. InterTrust ha^ infringed one or more claims of the '668 Patent, in violation 

of at least 35 U-S.C § 271(a, b, c). . j 

66. InterTrust's infrinfeement of the '668 Patent has caused and will continue to 

# i 

cause Microsoft damage, including irrepfarable harm for which it has no adequate remedy at law. 

PRAYER FOR RELIEF 
WHEREFORE, Microsoft prays for the following relief: 
A. * The Court enter judgment against InterTrust on 7 and dismiss with 
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1 | prejudice, any and all claims of the Second! Amended Complaint; 

B The Court enter jud pnent declaring that Microsoft has not infringed, 
3 I contributed to infringement of, or induced Infringement of the '683 Patent; 

C. The Court enter jud pent declaring that Microsoft has not infringed, 
contributed to infringement of, or induced infringement of the '193 Patent; 

D. The Court enter judgment declaring that Microsoft has not infringed, 
contributed to infringement of, or induceijinfringement of the '504 Patent; 

E. . The Court enter judgment declaring that Microsoft has not infringed, 
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9 contributed to infringement of, or bducediiiifringement of the '861 Patent; 

The Court enter judgment declaring that the '683 Patent is invalid; 

I 

The Conn enter judgment declaring that the ' 193 Patent is invalid; 
The Court enter judgment declaring that the '504 Patent is invalid; 



F. 
G. 
H. 
L 
J. 



The Court enter ju 



The Court enter judgment that the '861 Patent is unenforceable due to 



inequitable conduct; 

K. 
L. 
M. 



gment declaring that the '861 Patent is invalid; 



The Court enter judgment that InterTrust has infringed the '671 patent; 
The Court enter judgment that InterTrust has infringed the '668 patent; 
A permanent injur Sction prohibiting InterTrust, its officers, agents, servants, 
employees, and all persons in active, concbrt or participation with them from infringing the '67 1 
and '668 Patents; 

N. An award against InterTrust of damages and attorney fees, pursuant to the 

provisions of 35 U-S.C .§§ 284, 285. 

O. An award to Microsoft of prejudgment interest and the costs of this action. 

i 

P. The Coun award i!o Microsoft its reasonable costs and attorneys' fees; and 

i 

Q. The Court grant to 1 Microsoft such other and further relief as may be 
deemed just and appropriate. 

/// 
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Pursuant to Fed. R. Ciy 

trial by jury. 

DATED: September 17, 2001 
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Abstract 

Information Commerce is a business activity carried out among several parties in which information car- 
ries value and is treated as a product. The information may be content it may be returned usage and mar- 
keting data, and it may be representative of financial transactions* 

In each of these cases the information is valuable and must be kept secure and private. Traditional 
approaches secure the transmission of that information from one point to another; there are no persistent 
protections. Protection of all of these components of information commerce for all parties in a transaction 
value chain is necessary for a robust electronic infrastructure. 

A prerequisite to such an environment is a\ cryptographically protected container for packaging 
information and controls that enforce information rights. This paper describes such a container, called the 
DigiBox™. EPR has submitted initial specifications for the DigiBox container to the ANSI 11SP Electronic 
Publishing Task Force (EPUB) within the User/Content Provider Standards Working Group (WG4). 



1 Introduction truly support electronic commerce. These tools 

provide for the flow of products and services 
As services and products in modern commerce through creators 1 , providers', and users* hands, 
increasingly take electronic form, traditional com- They enable the creation, negotiation, and enforce- 
ment is evolving into electronic commerce. This meat of electronic agreements, including the evo^ 
includes both creation and enforcement of vario ( us lurion of controls that manage both the use and 
agreements between parties in an electronic com- consequences of use of electronic content or ser- 
mercial relationship. It also includes enforcing the vices. In addition, these tools support "evolving" 
rights of these parties with respect to the secure agreements that progressively reflect the require- 
management of electronic content or services ments of further participants in a commercial 
usage, billing, payment, and related activities. model. 

. „ Participants in electronic commerce [V] will need 

To save money, to be competitive, and to be effi- mles ^ mcchanisms that: 
cient [1,2], members of modem society will shortly 
bt using nffN information technology tools that 
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1 . Information providers can be assured that their 
content is used only in authorized ways; 

2. Privacy rights of users of content are pre- 
served; and 

3. Diverse business models related to content can 
be electronically implemented. ^ 

i 

The Internet and other information commerce 
infrastructures will require a management compo- 
nent that enforces such rules, ensuring a- safe, 
coherent, fair, and productive community. This 
management component will be critical to the elec- 
tronic highway's acceptance. Without rules to pro- 
tect the rights of content providers and • other 
electronic community members, the electronic 
highway will comprise nothing more than a collec- 
tion of limited, disconnected applications. 

Analysts have concluded that content will consti- 
tute the largest revenue-generating component of 
the information superhighway [5]. It is also clear 
that unfettered access to content requires that con- 
tent providers be able to maintain control over lit- 
erary or copyrighted assets. Many analysts 
conclude that this will be one of the key bottle- 
necks in the implementation and deployment of 
New Media. 



requires a substantial nianiifacuiring investment 
Figure 1 illustrates a simplified traditional informa- 
tion economy: physical goods flow from a pub- 
lisher (manufacturer) to a customer, in response to 
orders and followed by payments. The author's 
relationship with the publisher may be more light- 
weight, but the author is nonetheless dependent on 
the publisher to report sales and make royalty pay- 
ments in accordance with the author's contract In 
addition, a financial institution provides payment 
processing and clearing services for all parties. 



Financial 
Institution 




2 Information Commerce and Digital 
Value Chains 

Information commerce is often considered' a 
wholly new concept, made possible only through 
the use of networks and computers. In fact;' a 
robust information economy has existed foriccrrtu- 
ries, involving trafficking in physical representa- 
tions of information such as books, newspapers, 
and so on. Because such commerce involves) physi- 
cal goods, there is a non-negligible floor to the cost 
of handling information goods. The new aspects jof 
the electronic information economy are that the 
information itself is the entire product and that (the 
product can be distributed at negligible marginal 
cost. 

The traditional information economy in physical 
goods is publisher-centric, because creation' of 
information goods— particularly low-cost goods- 



Figure 1 . Traditional information economy. 

Because of the flexibility afforded by electronic 
mechanisms, information commerce is evolving 
from indirect, advertiser-supported, mass-audi- 
ence media to a new, niche-audience-oriented busi- 
ness model. In this system, members of the 
electronic community, with. or without the eco- 
nomic support of advertising, pay providers 
directly for what they want to receive. Business-to- 
business purchasing is steadily evolving into a 
direct electronic ordering model- 
Figure 2 illustrates the flexibility possible in new 
electronic information commerce models. 
Although there is still a role for publishers, this 
role no longer involves physical goods. Rather, the 
publisher is responsible for packaging and aggre- 
gating information goods and control information, 
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then making them available to customers. Similar 
to a manufacturmg/disrribution/retail chain for 
physical goods* the electronic model permits infor- 
mation retailers, and even end customers, to re- 
package and redistribute different aggregations .of 
information while ensuring that the appropriate 
control rules are maintained- A clearinghouse 
ensures that usage information and payments are 
provided directly to authors and publishers; the 
payments themselves are made through traditional 
financial institutions. Because control rules are 
associated with information, a variety of payment 
and other business models can be associated with 
the same content (e.g., purchase versus pay-per- 
use). •! 



2,1 Protecting All the Information In 
Information Commerce 

The very properties that make **the net* atttactive 
as a distribution medium — ease of manipulating 
information in electronic form — also appear to 
make these protections intractable. Addressing mis 
dichotomy requires a paradigm shift in computer 
architecture to introduce the concept of a "secure 
processing 1 ' environment in which protected infor- 
mation can be manipulated without being subject 
to external tampering or disclosure. A prerequisite 
to such an environment is a cryptographically pro- 
tected "container** for seamlessly packaging infor- 
mation and controls mat enforce information use 
rights. 



Author 



Financial 
Institution 



Content 




Payment 'j 
V Authorization* 



Aggregated Tsypaeni, 
Usage informiiioa ~ 



Publisher 
Distributes 



Clwinghoasc 




Customer 
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ContwvT 


Purchases 



Contrail 
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Content 




Redistributes 





Usage Reports 



a 



Figure 2. Electronic information economy. 



.A 1 . 

The conversion from traditional commercial distri- 
bution channels requires key foundation technolo- 
gies and results in a fundamental shift in existing 
infrastructures. This channel transformation jyill 
create a new electronic digital distribution industry. 
Digital distribution employing the DigiBox con- 
tainer architecture and its associated support envi- 
ronment, lnterTrust™, can play a critical role in 
this transformation of the communication, me^ia, 
and mformatLon technology markets. 



The DigiBox described by this paper is such a con- 
tainer 

The need for various information commerce com- 
puters and appliances to interoperate requires that 
this container format and its access methods be 
standardized EPR has submitted initial specifica- 
tions for the DigiBox container to the American 
National Standards Institute (ANSI) Information 
Infrastructure Standards Panel (IISP) through the 
Electronic Publishing Task Force (EPUB) in the 
User/Content Provider Standards Working Group 
(WG4). 

The primary goal of information protection is to 
permit proprietors of digital information (i.e., the 
artists, writers, distributors, packagers, market 
researchers, etc.) to have the same type and degree 
of control present in the "paper world." Because 
digital information is intangible and easily dupli- 
cated, those rights are difficult to enforce with con* 
ventional information processing technology. 
Many types of rights (compensation, distribution, 
modification, etc.) are associated with the various 
elements of information commerce, and these 
information property rights take many forms. At a 
high level, there is the legal definition of "copy- 
right," codified in U.S. law [6-9] and the Berne 
Convention. This gives copyright holders a legal 
right to control how copyrighted information is 
handled. In addition, various high-level rights are 
conferred by contractual arrangements between 
primary- rightsholders and other parties. 
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For example, the protections needed for conteit 
elements incorporate the licensing provisions for 
the intellectual property rights of the content rigty- 
sholders. In a broader sense, these rights include 
control over several activities: the right to be com- 
pensated for use of the property; the right to con- 
trol how content is distributed; the right to prevent 
modification of content by a distributor; "fair use" 
rights; the rights to the usage data, privacy rights tof 
individuals, and so on. ji 

:i 

In the realm of physical goods, these rights aje 
enforced by a combination of legal and technical 
means. However, the technical means can be (and 
are) unsophisticated because the technology for 
violating rights is relatively expensive and tunfe- 
consuming— in comparison to equivalent activities 
with respect to digital information. Photocopying a 
book or copying a video cassette is inherently mojre 
labor intensive and costly than copying a file: Sjo, 
while defeating technical means of enforcement jis 
(relatively) expensive, it can be done — and often 
the legal means to deter this are inadequate. •* 

i 

2,2 Information Commerce — Not Just U 

Payment ':' 

,i 

Rights protection is also a fundamental aspect jof 
commerce. Commerce is not just a way for two 
parties to pay each other for something. Rather; it 
is an extraordinarily rich web of relationships 
among parties that concerns payment, negotiation, 
control, advertising, reporting, auditing, and a vari- 
ety of other activities. These activities are impor- 
tant aspects of the transaction relationships. Often 
the information carried in these reports, audits^ a£nd 
the like is highly valuable and highly confidential, 
perhaps even more valuable than the content that is 
the subject of the information commerce at hajnd. 
These activities too are performed and controlled 
in the "paper world 1 1 by legal and technical means, 
but there are no widely used models for their etee- 



tronic equivalents. 



I 

Figure 3 shows some of the operations that could 
occur in true electronic commerce, using the Inter- 
net World-Wide Web [10] mechanisms as an exam- 
ple. Creators originate content and apply rules 
(e.g., "pay author Sl.OO/use") for its use. Distribu- 
tor tepaefcage content, applying additional rules 



(e.g., *pay $5.00 fox the collection, then pay the 
creator" "report use of each item"). Users receive 
content and operate on it, generating billing reports 
and usage reports mat are delivered to a clearing- 
house and paid or summarized back for the origi- 
. naring parties. This structure is very rich and is 
capable of supporting many business models. 
There arc multiple flows of iiifbrrnation in many 
different directions amongst the parties involved in 
the transactions. 

Another example is that of an advertiser (acting as 
distributor, or with a distributor). The advertiser 
might have a rule that offers a discount, or no 
charge at all, but only if the user views the adver- 
tisement and agrees to have that fact reported to the 
advertiser. 

It is relatively simple to devise schemes for parties 
to pay each other electronically (for example, Digi* 
Cash (11], NetBiU [12], Open Market [13], SNPP 
[14],NetChcque [15], First Virtual [16], etc.). Pay- 
ment, however, constitutes only one — and perhaps 
the simplest one — of the means in which parties in 
commerce interact All the other information com- 
merce components must be accomplished with the 
same needs for security, privacy, and integrity. In 
fact, these aspects of electronic commerce, includ- 
ing rights protection, are strongly intertwined in 
the digital economy, because much digital com- 
merce concerns information and innovative busi- 
ness models for information commerce. 

3 Existing Approaches to Information 
Commerce 

Information proprietors employ a variety of tech- 
nological protection approaches today. These 
approaches are generally "point solutions," in that 
they protect a specific type of property in a specific 
context and enforce only specifically defined 
rights — typically only the right to compensation 
for use. Because the technologies are limited, the 
maiket is fragmented, and there are no general pro- 
tection solutions-' . 
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Figure 3. Muki-party Internet information commerce. 



3.1 No Protection j 

j 

Much digital property is distributed without any 
technological enforcement for property rights, on 
the assumption that legal means suffice. This 
approach works well enough for many low-value 
properties, but it has the disadvantage of raising the 
price to legitimate usets who must pay for both 
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their own and illegitimate use. In many cases, how- 
ever, this cost is negligible, and no protection is an 
economically sound choice. Even for content that 
is free, however, a creator may wish to impose 
some rules for reporting or some access control. Of 
course, privacy rights of users will be a concern to 
many. 
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3,2 License Managers 

For some valuable software properties, license 
managers are used. Because a software property is 
dynamic (executable), it is feasible to restrict it so 
that it functions properly only through interaction 
with a license manager process. In general, there is 
no protection of usage data in these schemes. Lji 
some cases this technique has been applied to con- 
tent protection, but only with limited success [1T| F 
18]. * 

33 Cryptographic Unlock 

Some static properties (fonts, for example; also 
some installable software) are protected by a sim- 
ple ''unlock" scheme: a purchaser makes a pur- 
chase, for example by telephone with a credit carjjl, 
and receives a cryptographic key in return. This 
key can then be used to "unlock" one property 
from some widely distributed medium (e.g., CD- 
ROM or network download). This mechanism jjs 
relatively inflexible, and its inherently manual 
nature makes it expensive. 

3.4 Billing Schemes 



Various billing schemes (as mentioned above) per- 
mit purchase of information following what ;ts 
essentially an electronic check or electronic credit 
draft model. These methods are suitable for con- 
ventional transactions, but not for the . enormous 
volumes of Gndividually) very low-value transab- 
tions that would be generated using a complex dig- 
ital property. 

3.5 Secured Delivery 

Various secured delivery systems (e.g., SSL [19], 
SHTTP [20]) share the same problems as crypto- 
graphic unlock, but in a network context They are 
only point-to-point solutions, with the mformatfon 
(content, usage data, etc.) at each site being left 
unprotected once the delivery has occurred. Fur- 
thermore, they are inherently online systems: it is 
not practical to decouple the delivery of informa- 
tion from payment for its use. 



4 : Information Protection Architecture: 
' .Interlrust and DigiBox 

EPR has produced the InterTrust Virtual Distribu- 
tion Architecture to solve unmet, critical needs of 
electronic commerce. Almost any imaginable 
information transaction can be supported by Inter- 
Trust A few examples include distribution of con- 
tent (eg*, text, video, audio) over networks, 
selective release of data from a database, con- 
trolled release of sensitive information, and so on. 
InterTrust can also support the secure communica- 
tion of private information such as EDI and elec- 
tronic financial transactions, as well as delivery of 
the- "back channel" marketing and usage data 
resulting from transactions. 

DigiBox is a foundation technology within Inter- 
Trust It provides a secure container to package 
information so that the information cannot be used 
except as provided by the rules and controls associ- 
ated with the content InterTrust rules and controls 
specify what types of content usage are permitted, 
as well as the consequences of usage such as 
reporting and payment. 

Within InterTrust, DigiBox containers can enforce 
a* "distributed electronic contract" for value-chain 
activities functioning within an electronic distribu- 
tion environment This unique approach underlies 
EPR's information metering and digital rights pro- 
tection technology. Electronic commerce infra- 
structure participants can use InterTrust to 
substantially enhance their network, security, or 
payment method solutions. 

The DigiBox is a container for both digital prop- 
erty (content) and controls. It is used in conjunc- 
tion with a locally secured rights protection 
application (discussed further below) to make con- 
tent available as governed by arbitrarily flexible 
controls. 

The DigiBox container mechanism is implemented 
in! a set of platform-independent class libraries that 
provide access to objects in the container and 
extensions to OpenDoc and OLE object technolo- 
gies. DigiBox allows rights management compo- 
nents to be integrated with content in highly 
flexible and configurable control structures. Digi- 
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Box rights management components can be inte 
grated with content in a single deliverable, or somu 
or all of the components can be delivered indepen-ij 
dently. DigiBox rights management component^ 
enable true superdistribution [21] and can support,' 
virtually any network topology and any number ofi 
participants, including distributors, ledistributorsj 
information retailers, corporate content users* and 
consumers. 

4.1 Content 

The digital information in a DigiBox (one or roox 
^roperies") is information in any form. It may r 
mapped to a specific compound object format (eg. 1 , 
OpenDoc, OLE, PDF), or may be application spe| 
cific. 3 

Further, it may be delivered in stream or other 
communication-oriented forms, not just in a files 
like container. 

4.2 Controls 

Controls specify rules and consequences for opera 
tions on content. Controls are also delivered in ja 
DigiBox, and the controls for a property may tot 
delivered cither with the property or mdependcntly. 
Controls arc tied to properties by cryptographic 
means. 



Because controls can be delivered with properties 
in a container, the DigiBox supports Bupeidistribd- 
tion. 1 

4.3 Commerce 

Commerce takes place governed by controls, 
may involve metering, billing for use, reporting of 
usage, and so on. These operations take place 
locally in a secure environment, and they generate 
audit trails and reports that must be reported peri- 
odically to clearinghouses. \\ 



5 DigiBox Implementation 

The DigiBox is a structure that can hold, in a pro- 
tected manner, information commerce elements of 
ill taldS'. conlfittt; usage information, representa- 



tion of financial transactions (e.g., electronic cash), 
and! other digital elements of ^formation com- 
merce. . 
I 

5.1 i Container Logical Structure 

i * 

Figure 4 shows the logical structure of properties 
and' control sets in two containers. Container Cj- 
holcls'two properties, Pt and Pj, and one control set, 
CSj, that applies to property P|; container Q con- 
tains two control sets and no properties. As shown 
■in the example, each of these elements -has a title 
attribute to provide a human-readable description 
of the element and, for control sets, an attribute 
indicating to what other elements the control set 
applies, 
i 

A control set specifies rules and consequences, 
such as pricing, reporting, and so on, for the prop- 
erties to which h applies. A user holding just this 
container could use (e.g., view, print) content from 
PjJ-though only as specified by CSj. Because 
there is no control set applying to P 2 in that con- 
tainer, Pj would not be usable in any way. 
i 

A user holding both containers could use property 
pj as specified by CS 2 , and in addition has the 
choice of whether to designate CS, or CS 3 when 
using P,. CS„ which describes itself as "discount," 
is likely to be the user's preferred choice. 

The (DigiBox includes several elements: organiza- 
tional structures, properties, controls, and support- 
ing data items. Almost all the information in a 
DjgiBox is encrypted, as described below, and 
access to the encrypted form is provided through a 
storage manager as appropriate, depending on how 
the DigiBox is delivered (e.g., as a file or as a data 
stream). 

Sil Container Physical Structure 

Figure 5 is a schematic picture illustrating the 
physical structure of a DigiBox container. (Some 
elements have been omitted for clarity.) It begins 
with a container header structure containing 
descriptive and organizational information about 
the container. Part of the container header is 
encrypted (both for secrecy and for integrity pro- 
tection); .the rest is public organizational informa- 
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Property 
Pi 



Title «= giraffe 




Control Set 



Applies to = Pj 



Title = regular 



Property 
*2 



Title = elephant 



Container C 



Figure 4. Container logical structure. 



tion. The header is followed by 



additional 

_ — I| 

container-wide structures such as the transport kkv 
block (TKB) and the container table of contents 
(TOQt some of which arc encrypted and othep 

These organizational elements are followed by the 
structures defining the container's content (e.g., 
properties and control sets)- As shown in the fig- 
ure, a property is represented by a property header, 
property attributes, and data blocks composing the 
property. As shown, the header is encrypted and 



,i 



: Control Set 
CS 3 



Applies to = Pi 



Title = discount 



Control Set 
CS 2 



Applies to = P 2 



Title = discount 



Container C 2 



the attributes are not; the data blocks may be 
wholly or partly encrypted, or not at all, depending 
on security requirements. 

The figure shows an example property consisting 
of a jmultimedia property formed from a pair of 
synchronized data streams for audio and video. In 
this jexample, each video block is mostly unen- 
crypted so that access can be rapid while still main- 
taining reasonable security — encrypting even 10 
percent of an MPEG stream renders it effectively 
useless for illicit copying. On the other hand, the 
audio is entirely encrypted, and each audio block 
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Figure 5. Container physical format 



uses four distinct keys, because the content propri ■ 
dor requires much stronger security for audio than 
for video. 

A property is represented as one or more properly 
sections, each of which is independently associate^ 
with control information, and which may also b e 
stored and accessed independently. A property, ft r 
example, might be a collection of clip-art images, 
and each image might be a property "chunk," wii h 
its own control specifying how that image's creat< i 
is compensated. 

Controls can map to property chunks at arbitrary 
granularity and can enforce arbitrary organiza- 
tional structures within the property (such as a file 
. hierarchy). Controls can apply to individual bytes, 
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Property P | Data 



fxames of a movie, segments of a musical piece, 
arid sp on, because the mapping is performed by a 
control process specified by the control structure, 
not simply via a table-driven data structure. 

If » 

i i j 

5 ! i3 ! ! Cryptographic Techniques 

1 . ; 

Tjbei ■ high-level elements in a DigiBox are 
encrypted with a transport key that is normally 
derived (by exclusive OR) from two parts: one that 
is] delivered in the DigiBox itself, encrypted with a 
public key algorithm, and the other that is stored in 
protected storage locally. The locally stored part is 
snared among all the local nodes capable of pro- 
cessing that DigiBox, but the part in the DigiBox is 
unique. This separation provides protection against 
accidental or malicious disclosure of either part 



09/28/2001 09:28 FAX 415 394 0134 



MKER & VAN NEST LLP 



In Container 



Transport Key 
Block (TKB) 



ID= 1 


yyyyyyyy> 


ID = 5 




ID = 31 


Partial TK 


ID* 36 




ID =40 




ID = 6l 





Container 
Header 



Info; 



Public 
eader 
"ormation 



Encrypted 

Header 
Information 





@029 



Decrypted Header Information 
Figure 6. Container transport security. 



Figure 6 illustrates how the transport key (TK) is 
derived. The transport key block (TKB) contains 
one or more slots, each of which contains a partial 



In Protected 
Local Storage 



TKEK 
Storage 



n> = 6 


TKEK* 


TDO 


TKEK 7 


ID = 8 


TKEK 8 


ID = 30 


TKEK3Q 


ID^31 


TKEK31 


ID = 32 


TKEK32 


rr>i=33 


TKEK33 



Partial TK 
Storage 



ID = 73 


. Partial TK73 


ID = 81 


Partial TK^ 


ID -90 


Partial TK^ 


ID = 142 


Partial TK l42 


ID =176 


Partial TK 176 


ID -177 


Partial TK177 



transport key encrypted under a different transport 
key encrypting key (TKEK). Each TKB slot identi- 
fies the TKEK used, and a matching TKEK is 
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selected from local protected storage. Decrypting 
the slot yields a partial TK, which is combined 
with its corresponding partial TK again from.'pro- 
tected local storage to yield the actual TK for 
decrypting the container header. 

The data for the property itself is encrypted s with 
other keys ("content keys") that are themselves 
delivered in encrypted high-level structures? this 
approach permits the keys for a property to be 
delivered entirely separately from the property or 
its controls. Multiple keys, in a wide variety of 
key-mapping schemes, are used to encrypt the 
data, limiting the loss that would occur from dis; 
closure of any one key. j 

I 

; i 

All DigiBox control structures are bom encrypted 
and verified for integrity with a cryptographic hash 
function. Several cryptographic ^gorithms are 
supported for these control structures (principally 
for export control reasons), and arbitrary! algo- 
rithms are supported for encryption of the data. 



In 

use [ill 
wa:e 
apf Ucations, 
low 

business)' 
likely 
is 

it rkvei 
be supported) 
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5.4 Security Characteristics 



Electronic commerce, and information commerce 
in particular, needs a robust information protection 
m ichanism, including rights protection and con- 
trols, not just payment systems. As the electronic 
, w! »rld evolves, however, and moves forward from 
The DigiBox cryptographic structures are designei s iop\y emulating traditional transactions into 

er tirely new business models, rights protection and 
c< ntrol will become the predominant issues, 



to be secure even in the face of loss of individuil 
key components, and to minimize the damage in 
case a key or processing environment is comprc- 
miscd. The system is designed to provide commer- 
cially acceptable risks and losses for a variety of 
business models. I 



The basic algorithms are strong: Triple D^S [22] 
and RSA [23] are preferred. This security, is, of 
course, only as strong as the tamper-resistance of 
the local processing environment. The preferred 
implementation of. DigiBox processing relics on|a 
"secure processing unit" (SPU) that contains ja 
CPU, memory, program storage, and key storage in 
a single tamper-resistant hardware packagf. 
Although these are not widely available tod>y, the 
variety of applications they might support makesfit 
likely that such SPUs will become widely inte- 
grated into common computing platforms. When 
running in an SPU, the DigiBox processing and 
control mechanisms are sufficiently well protected 
to support most commerce applications. 
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he absence of an SPU, other approaches are 
__ for many business models. In fact, a soft- 
.-only implementation is sufficient for many 
ications, because much content is of relatively - 
valve and is used in a context (business to 
where a modest level of fraud is both less 
and more tolerable. As long as me software 
rjioderately difficult to defeat and tools to defeat 
no legitimate purpose, business models can 
where some risk of loss is acceptable. 
* he world of electronic commerce, just as for au- 
ditorial commerce, security is not absolute: it is 
jus t a factor to balance against the cost of loss and 
fraud 



Conclusions 

Trie DigiBox is one component of a general-pur- 
pdse electronic commerce solution mat rests on 
thi ee basic principles: rights protection, interopera- 
bi] ity, and strong security. 



Protection of intellectual property rights in infor- 
m ition requires strong cryptography as well as a 
flexible inrrastmcture for controlling use of the 
information. A standard protected container for 
it formation is necessary to support interoperabfl- 
j t f — most existing schemes rightly bind the creator 
o 'protected information and the software that pro- 
cesses it. A standard container can rationalize 
ir formation commerce and reduce costs for all par- 
ti ;ipants. 

h i the long term, general-purpose secure electronic 
ommerce will need pervasive deployment of 
ti mper-resistant hardware devices to perform 
secure processing of protected content. However, 
as these solutions are developed, many business 
models can be accommodated with weaker or less 
complete solutions because the risk and expected 
losses are commercially acceptable. 
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Bustoess-to-business purchasing is steadily evolv- 
ing into a direct electronic ordering model. Future 
communications and media markets will become 
increasingly segmented and, specialized; in 
response to customer preferences and needs] and 
involve increasing, and more sophisticated, direct 
interaction between consumers and providers. 
These markets and their value chains (with or with- 
out intermediary distributors) will require secure 
metering and control tools that enable a user to 
efficiently and economically tailor resources to tis 
or her own desires. 

During the next decade, digital delivery of tradi- 
tional electronic products, such as mfoimaripn 
databases and software, will be joined by a ntpidl> 
growing array of bom New Media and electron* 
cally distributed traditional content The convex 
sion from traditional models requires! 
foundation technologies and will result in a funda 
mental shift in current infrastructure. This transfer 
mation will create a new distribution industry 
Digital distribution employing a universal conten 
and commerce container can play a critical role b 
this broad economic transformation. ] 

j 
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